漏洞库 第40页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4302: Stop User Enumeration WordPress plugin – Authentication Bypass

漏洞标题 CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass 漏洞描述 Stop User Enumeration WordPress plugin < 1.7.3 contains an authentication bypass ...
CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload

漏洞标题 CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload 漏洞描述 The Migration, Backup, Staging – WPvivid Backu...
CVE-2025-51586: PrestaShop - Information Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-51586: PrestaShop – Information Disclosure

漏洞标题 CVE-2025-51586: PrestaShop - Information Disclosure 漏洞描述 User enumeration vulnerability in the AdminLogin controller in PrestaShop 1.7 through 8.2.2 allows remote atta...
CVE-2025-53771: Microsoft SharePoint Server - Authentication Bypass (ToolShell)-渗透云记 - 专注于网络安全与技术分享

CVE-2025-53771: Microsoft SharePoint Server – Authentication Bypass (ToolShell)

漏洞标题 CVE-2025-53771: Microsoft SharePoint Server - Authentication Bypass (ToolShell) 漏洞描述 Microsoft Office SharePoint Server contains an improper authentication vulnerabili...
CVE-2025-34077: WordPress Pie Register <= 3.7.1.4 - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34077: WordPress Pie Register <= 3.7.1.4 - Authentication Bypass

漏洞标题 CVE-2025-34077: WordPress Pie Register <= 3.7.1.4 - Authentication Bypass 漏洞描述 An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤...
CVE-2025-2747: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0006)-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2747: Kentico Xperience 13 CMS – Staging Service Authentication Bypass (WT-2025-0006)

漏洞标题 CVE-2025-2747: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0006) 漏洞描述 An authentication bypass vulnerability in Kentico Xperience allows ...
CVE-2025-34291: Langflow AI <= 1.6.9 - CORS Misconfiguration-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34291: Langflow AI <= 1.6.9 - CORS Misconfiguration

漏洞标题 CVE-2025-34291: Langflow AI <= 1.6.9 - CORS Misconfiguration 漏洞描述 Langflow AI versions 1.6.9 and earlier are vulnerable to a CORS misconfiguration that allows any o...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月4日 10:39
20
CVE-2025-34143: ETQ Reliance - Authentication Bypass via Trailing Space-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34143: ETQ Reliance – Authentication Bypass via Trailing Space

漏洞标题 CVE-2025-34143: ETQ Reliance - Authentication Bypass via Trailing Space 漏洞描述 An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform....
CVE-2025-2907: Order Delivery Date Pro for WooCommerce < 12.3.1 - Arbitrary Option Update-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2907: Order Delivery Date Pro for WooCommerce < 12.3.1 - Arbitrary Option Update

漏洞标题 CVE-2025-2907: Order Delivery Date Pro for WooCommerce < 12.3.1 - Arbitrary Option Update 漏洞描述 The Order Delivery Date WordPress plugin before 12.3.1 does not have ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月4日 05:45
20
CVE-2025-51502: Microweber CMS 2.0 - Reflected XSS in Admin Page Creation-渗透云记 - 专注于网络安全与技术分享

CVE-2025-51502: Microweber CMS 2.0 – Reflected XSS in Admin Page Creation

漏洞标题 CVE-2025-51502: Microweber CMS 2.0 - Reflected XSS in Admin Page Creation 漏洞描述 Reflected Cross-Site Scripting (XSS) exists in Microweber CMS 2.0 through the layout par...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月3日 21:33
20
CVE-2025-32433: Erlang/OTP SSH - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-32433: Erlang/OTP SSH – Remote Code Execution

漏洞标题 CVE-2025-32433: Erlang/OTP SSH - Remote Code Execution 漏洞描述 Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26....
CVE-2025-41243: Spring Cloud Gateway Server Webflux - Broken Access Control-渗透云记 - 专注于网络安全与技术分享

CVE-2025-41243: Spring Cloud Gateway Server Webflux – Broken Access Control

漏洞标题 CVE-2025-41243: Spring Cloud Gateway Server Webflux - Broken Access Control 漏洞描述 Spring Cloud Gateway Server Webflux contains a vulnerability caused by unsecured and e...
CVE-2025-11749: WordPress AI Engine Plugin - Token Exposure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-11749: WordPress AI Engine Plugin – Token Exposure

漏洞标题 CVE-2025-11749: WordPress AI Engine Plugin - Token Exposure 漏洞描述 Unauthenticated sensitive information exposure in AI Engine WordPress plugin <= 3.1.3 exposes beare...
CVE-2025-34509: Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded Credentials-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34509: Sitecore Experience Manager (XM) and Experience Platform (XP) – Hardcoded Credentials

漏洞标题 CVE-2025-34509: Sitecore Experience Manager (XM) and Experience Platform (XP) - Hardcoded Credentials 漏洞描述 Sitecore Experience Manager (XM) and Experience Platform (XP...
CVE-2025-26319: FlowiseAI Flowise <= 2.2.6 - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2025-26319: FlowiseAI Flowise <= 2.2.6 - Arbitrary File Upload

漏洞标题 CVE-2025-26319: FlowiseAI Flowise <= 2.2.6 - Arbitrary File Upload 漏洞描述 FlowiseAI Flowise version 2.2.6 and below contains an arbitrary file upload vulnerability in...
CVE-2025-2010: WordPress JobWP Plugin <= 2.3.9 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2010: WordPress JobWP Plugin <= 2.3.9 - SQL Injection

漏洞标题 CVE-2025-2010: WordPress JobWP Plugin <= 2.3.9 - SQL Injection 漏洞描述 The JobWP - Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is v...